Junglewise Threat Intelligence

CVE-2026-90404: Linux kernel cros_ec_debugfs use-after-free via unregistered panic notifier

CVE-2026-90404 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ChromeOS EC debug file system driver fails to unregister a panic event handler during shutdown, leaving a dangling callback registered. When the system panics after the driver is unloaded, the stale callback executes and accesses freed memory, potentially causing a kernel crash or memory corruption.

Technical details

The vulnerability is a use-after-free in the cros_ec_debugfs driver. During probe, cros_ec_debugfs_probe() registers a panic notifier (notifier_panic) with the EC panic notifier chain. However, the remove path (cros_ec_debugfs_remove()) tears down debugfs and console log state without unregistering this notifier. If a panic occurs after the driver is removed, the notifier callback executes and queues work that accesses the freed debug_info structure. The fix adds a call to blocking_notifier_chain_unregister() before resource cleanup. This issue was discovered via static analysis and does not require elevated privileges or network access—it only needs a system panic event, which could be triggered locally on an affected ChromeOS device.

Affected products

  • Linux Linux kernel 5.10 and later (cros_ec driver)

Timeline

  • 2026-09-17: disclosed: CVE-2026-90404 published
  • 2026-09-14: patched: Fix merged into Linux stable trees

References

Related threats